PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97442 Linux CVE debrief

A vulnerability in the Linux kernel's ath11k driver can lead to invalid data access and memory corruption due to a missing sanity check for packet lengths in certain Wi-Fi header cases. This vulnerability requires a patch to prevent potential memory corruption or invalid data access issues. Linux kernel maintainers, ath11k driver users, and system administrators responsible for Wi-Fi network security should assess exposure and apply the patch. The patch adds a sanity check to prevent exploitation and has been adapted from the discussion/patch of the ath12k driver.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-25
Advisory published
2026-09-24
Advisory updated
2026-09-25

Who should care

Linux kernel maintainers, ath11k driver users, and system administrators responsible for Wi-Fi network security should assess exposure and apply the patch to prevent potential memory corruption or invalid data access issues.

Why it matters

A vulnerability in the Linux kernel's ath11k driver requires a patch to prevent potential memory corruption or invalid data access issues. Linux kernel maintainers, ath11k driver users, and system administrators responsible for Wi-Fi network security should assess exposure and apply the patch.

  • Potential memory corruption or invalid data access issues require verification and patching
  • Wi-Fi network security may be compromised if patch is not applied
  • System administrators should verify system configurations and Wi-Fi header lengths

Technical summary

The Linux kernel's ath11k driver is vulnerable to invalid data access and memory corruption due to a missing sanity check for packet lengths in certain Wi-Fi header cases. A patch has been applied to add a sanity check and prevent exploitation. The patch was adapted from the discussion/patch of the ath12k driver and was tested on WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1. Linux kernel maintainers, ath11k driver users, and system administrators responsible for Wi-Fi network security should assess exposure and apply the patch.

Defensive priority

High

Recommended defensive actions

  • Review and apply the Linux kernel patch to add a sanity check for packet lengths in the ath11k driver
  • Monitor system logs for potential memory corruption or invalid data access issues
  • Verify system configurations and Wi-Fi header lengths to prevent exploitation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including a CVSS score of 8.8 and a HIGH severity rating. The Linux kernel patch adds a sanity check to prevent invalid data access. The patch was tested on WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1. The vulnerability was resolved in the Linux kernel, and the patch is available for affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97442 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97442

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97442 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97442

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/00738665c875ab34efa7126ea63c9d70b48ee169

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1c0a13be76db3c1cf774aa11d9f4c3f8239ac567

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6b471e9aefee9ed73278eb1141e0d8530a56fae9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.